NAIC 668 Compliance Checklist: What Your Information Security Program Needs
A NAIC 668 compliance checklist covers four requirements set out in Section 4 of the model law. This guide breaks each one into plain steps you can act on.
This checklist assumes you already know the law applies to you. If you’re not sure yet, start with what NAIC Model Law 668 actually is or check whether your state has adopted it.
If you’re a Chicagoland insurer, agency, or MGA, you’re already on the clock.
Key Takeaways
- Build a written Information Security Program covering administrative, technical, and physical safeguards for Nonpublic Information, scaled to your size and complexity.
- Investigate every Cybersecurity Event using a written incident response plan, not an ad hoc scramble.
- Notify your state Commissioner within 72 hours of determining a Cybersecurity Event occurred, when the notification triggers apply to you.
- Certify compliance in writing every February 15 and keep supporting records for five years.
The Information Security Program: What You Have to Build
Section 4C and 4D of the model law spell out the building blocks of your Information Security Program. Here’s each requirement translated into plain English, with a note on what it typically looks like inside a small agency or insurer.
| Requirement | What the Law Requires | What It Looks Like in a Small Agency |
|---|---|---|
| Named responsible person | You must designate a person responsible for the program. | Often the owner or office manager, named in writing, not necessarily a dedicated security hire. |
| Written risk assessment | Identify foreseeable internal and external threats, assess their likelihood and damage, and reassess at least annually. | A short written document reviewed once a year and updated after any major change. |
| Access controls and MFA | Limit access to Authorized Individuals and use effective controls, which may include Multi-Factor Authentication. | MFA turned on for email, cloud file storage, and any system holding Nonpublic Information. |
| Encryption in transit and at rest | Encrypt Nonpublic Information sent over external networks and stored on portable devices. | Encrypted email for client files, plus encrypted laptops and phones. |
| Secure disposal | Document procedures for securely disposing of Nonpublic Information. | A shredding policy for paper and a wipe procedure for retired hard drives. |
| Testing and monitoring | Test and monitor systems regularly for intrusions. | Managed detection tooling and periodic vulnerability scans, usually run by an IT partner. |
| Audit trails | Maintain audit trails able to detect and reconstruct Cybersecurity Events. | Centralized logging kept long enough to investigate an incident after the fact. |
| Environmental safeguards | Protect against fire, water damage, and other environmental hazards. | Fire suppression in a server room, or simply moving servers to a cloud provider that already handles this. |
Every item on this table has to be “commensurate with the size and complexity” of your business.
The Governance Layer: Who Signs Off and When
Section 4 doesn’t stop at technical controls. It also requires oversight from the top of the organization, not just the IT department.
| Requirement | What It Requires | When It’s Due |
|---|---|---|
| Board or committee report | If you have a board, it (or a committee) must require management to report in writing at least annually on the program’s status, risk assessment, testing results, and any Cybersecurity Events. | At least once a year. |
| Written incident response plan | Cover your internal response process, roles and decision-making authority, communications, remediation, documentation, and plan review after an event. | In place before an event happens, not written during one. |
| Annual certification | Submit a written statement to the Commissioner certifying Section 4 compliance, and retain supporting records for examination. | Every February 15, records kept five years. |
The board-report and certification requirements exist for the same reason: the model law wants compliance to be a leadership decision with a paper trail, not something that lives only in an IT ticketing system. If your program has gaps, the certification requirement doesn’t disappear. You document the remedial work planned and underway instead of leaving the box unchecked.
Who Owns What: IT Partner vs. Your Leadership Team
Not every item on the checklist above belongs to the same person. Some of it is a technical build. Some of it is a leadership decision that no vendor can make for you.
| Section 4 Requirement | Who Typically Owns It | Why |
|---|---|---|
| Access controls and MFA | IT/MSP partner | Configuring and maintaining login controls is a technical build. |
| Encryption in transit and at rest | IT/MSP partner | Requires the right tools, set up correctly, and kept current. |
| Testing and monitoring | IT/MSP partner | Needs ongoing tooling and someone watching the alerts. |
| Audit trails | IT/MSP partner | Centralized logging is infrastructure work. |
| Environmental safeguards | IT/MSP partner | Often solved by moving to a cloud provider that already handles it. |
| Secure disposal procedures | Shared | IT executes the wipe or shred; leadership sets the written policy. |
| Named responsible person | Your leadership | The law requires a designated person, not a vendor’s name on a contract. |
| Written risk assessment | Your leadership (IT-informed) | Leadership owns the sign-off even when IT supplies the technical findings. |
| Board or committee report | Your leadership | Only your board can report to your board. |
| Third-party vendor due diligence | Your leadership | You choose and vet your own vendors, including your IT partner. |
| Written incident response plan | Shared | IT builds the technical response; leadership owns roles and decision authority. |
| Annual certification to the Commissioner | Your leadership | Only an officer of the licensee can certify compliance. |
A managed IT partner can operate most of the technical rows in that table day to day. LeadingIT’s insurance and compliance IT services are built around exactly those Section 4 categories: MFA and access controls, encryption, monitoring, logging, and secure disposal. What a vendor cannot do is sign your certification or sit on your board. Those rows stay with you no matter who you hire.
This split matters because examiners under Section 7 don’t just check whether MFA is turned on. They check whether the paperwork behind it, the risk assessment, the board report, the vendor due-diligence file, actually exists. A good IT partner helps produce that documentation. It’s still your name on the certification.
The Exemption Trap: “We’re Exempt” Doesn’t Mean “We’re Done”

Section 9 of the model law exempts three groups from building a full Information Security Program: licensees with fewer than 10 employees (including contractors), licensees already compliant with HIPAA’s security rules, and employees or agents already covered by another licensee’s program.
Even a licensee exempt under Section 9 must still submit a written certification claiming the exemption. Exemption is not the same as no paperwork.
That last point trips up a lot of small agencies. The HIPAA exemption in particular requires an affirmative written certification of that HIPAA compliance. You can’t just assume the exemption applies and move on. You have to document it.
There’s also a clock most people miss. If your agency grows past 10 employees, or you drop out of HIPAA compliance, you don’t get to keep operating under the old exemption indefinitely. You get 180 days to come into full Section 4 compliance from the moment you stop qualifying.
A few situations where the exemption trap shows up in practice:
- An agency hires its 10th employee or contractor and doesn’t realize the clock started.
- A licensee lets its HIPAA compliance lapse (a missed risk analysis, an expired BAA) without noticing the NAIC 668 exemption lapsed with it.
- An agent assumes their carrier’s program covers them, when the relationship doesn’t actually meet the Section 9(C) carve-out.
If you’re not certain which category you fall into, that’s worth resolving before February 15, not after.
See Where You Stand
Not sure if your current setup would hold up under a Section 7 examination? Answer 8 plain-English questions and see your compliance-readiness level and the specific gaps to fix. No sign-up required to see your result.
Take the free 2-minute NAIC 668 Risk-Check
Related Guides
- What Is NAIC Model Law 668? Insurance Data Security Explained
- Does My State Have an Insurance Cybersecurity Law?
Frequently Asked Questions
As promptly as possible, and no later than 72 hours from determining a Cybersecurity Event occurred. Your notification needs to cover specifics like when it happened, how you found it, and what data was affected.
Yes. The model law requires you to reassess the effectiveness of your key controls, systems, and procedures no less than annually. It doesn’t have to be a massive undertaking every time, but it can’t be a one-time document you file away.
You’re exempt from building the full Information Security Program under Section 9, but you still have to submit a written certification claiming that exemption. Fewer than 10 employees, including contractors, is the threshold. If you cross it, you have 180 days to build a compliant program.
You qualify for an exemption from the full Section 4 program, but only if you certify that HIPAA compliance in writing. It’s not automatic. And if your HIPAA compliance lapses for any reason, you have 180 days to come into full NAIC 668 compliance from that point.
You get 180 days from the point you stop qualifying to build and implement a full Section 4 Information Security Program. That includes the risk assessment, the security measures, the incident response plan, and everything else on this checklist. The clock doesn’t wait for your next renewal date.
Each insurer domiciled in an adopting state must submit a written statement to the Commissioner by February 15 each year, certifying compliance with Section 4. You also have to keep the supporting records, schedules, and data for five years in case the Department examines them.
No. It’s a model law, not a federal statute, so it only takes effect once a state adopts it, and the exact citation and enforcement details vary by state. If you operate in multiple states, check each one’s adoption status separately.
Building Your Program Without Building It Alone
Most of this checklist is achievable with the right IT partner handling the technical rows and your leadership owning the governance rows. The hard part is usually documentation, not technology.
LeadingIT works with Chicagoland insurance agencies, MGAs, and insurers on the technical side of Section 4: access controls, MFA, encryption, monitoring, audit trails, and secure disposal, plus the documentation an examiner would ask to see. See our insurance compliance IT services or book a call to walk through where your program stands today. Questions first?
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
